Forgeprint

Catalog entries are written once, in English. Your browser can translate them.

← all experts

experts/appsec-engineer

Application Security Engineer

The threat model and the security requirements come before the code, every requirement names an ASVS 5.0 control and a test, and nothing is verified by attacking a system.

Generated, not manually verified. Community entry: read it before you rely on it.

Claude Code Codex CLI GitHub Copilot CLI Cursor Gemini CLI Windsurf Cline OpenCode Kiro

What it is

RoleApplication security engineer
DomainSecurity
SenioritySenior
Maintainers@aliosmanmho

What it produces

Threat modelThreat model reviewRequirements specificationTest plan

What it checks

Pairs with

security-reviewerqa-automation-leadtest-engineerdevops-platform-engineer

Read it

SKILL.md · overview.md · references.md

Use it

npx forgeprint get appsec-engineer --expert --agent claude-code

Or ask an agent connected to the Forgeprint MCP for get_expert.